ShadowTalk: Powered by ReliaQuest

ShadowTalk: Powered by ReliaQuest

Download on the App Store

ShadowTalk: Powered by ReliaQuest episodes

  • Weekly: 2023 in Review, ALPHV Targeted by FBI, Predictions for 2024

    In this episode of ShadowTalk, host Chris, along with Rick and Kim, discuss the latest news in cyber security and threat research.  Topics this week include:

    • ALPHV targeted in law enforcement operation
    • A look back at major events from the previous 12 months
    • Predictions for the cyber threat landscape in 2024
    • 'Expense in depth' and maximising investments

    Resources:

    • https://www.reliaquest.com/blog/double-extortion-attack-analysis/
    • https://www.reliaquest.com/blog/alphv-ransomware-site-outage/ 
    • https://www.justice.gov/media/1329536/dl?inline=&utm_medium=email&utm_source=govdelivery
    49 min
  • Weekly: BYOVD Report, Log4Shell Two Years Later, ALPHV Site Outage, Delaying SEC Disclosures

    In this episode of ShadowTalk, host Corey Carter, along with ReliaQuest CISO Rick Holland and Gjergji Paco, discuss the latest news in cyber security and threat research.  Topics this week include:

    • An overview of a ReliaQuest report on a sophisticated incident involving a technique known as Bring Your Own Vulnerable Driver (BYOVD).
    • ALPHV ransomware site outage rumored to be caused by law enforcement.
    • Apps vulnerable to Log4Shell still being exploited by Advanced Persistence Threats.
    • FBI releases policy notice that informs cyber victims how they can request to delay public disclosures to the Securities and Exchange Commission.

    Resources:

    • https://www.sonatype.com/resources/log4j-vulnerability-resource-center
    • https://blog.talosintelligence.com/lazarus_new_rats_dlang_and_telegram/
    • https://www.reliaquest.com/blog/alphv-ransomware-site-outage/
    • https://www.fbi.gov/file-repository/fbi-policy-notice-120623.pdf/view
    • https://www.kovrr.com/blog-post/cybersecurity-legal-and-financial-experts-share-their-reactions-to-the-secs-latest-cyber-disclosure-regulations
    36 min
  • Weekly: Ransomware Targeting ESXi, Threats to Airline Organizations, CNI Impacted

    In this episode of ShadowTalk, host Chris, along with Caroline and James, discuss the latest news in cyber security and threat research. Topics this week include:

    • Ransomware groups increasingly targeting ESXi
    • Cyber Threats to the Airline industry
    • Incidents affecting CNI in the US, UK, and Israel

    Resources:

    • https://www.gov.uk/government/news/response-to-a-news-report-on-cyber-security-at-sellafield
    • https://www.cshub.com/attacks/news/lockbit-hackers-publish-43gb-of-stolen-boeing-data-following-cyber-attack
    • https://www.theregister.com/2023/11/29/water_authority_ciso_iran/
    • https://www.bleepingcomputer.com/news/security/linux-version-of-qilin-ransomware-focuses-on-vmware-esxi/
    30 min
  • Weekly: EDR Pitfalls, Okta Intrusion Update, Secure AI Guidelines, Expired Google Cookies

    In this episode of ShadowTalk, host Corey, along with Rick, Marken, and James, discuss the latest news in cyber security and threat research. 
     Topics this week include:

    • An overview of ReliaQuest's latest report covering EDR Pitfalls and Best Practices.
    • Latest updates to Okta's Support Case Management System intrusion that occurred in October.
    • Discussion on guidelines released for secure AI system development by CISA and UK NCSC.
    • Infostealers making headlines after allegedly being able to restore expired Google cookies.

     

    Resources:

    Okta's Support Case Management System Intrusion Update-
    https://sec.okta.com/harfiles

    Proactive Defense: Positioning your IR Team for Success webinar-
    https://event.on24.com/wcc/r/4388361/F9C6D55AEEB34F33683F29973F48D174?partnerref=shadowtalk

     CISA and UK NCSC Joint Guidelines-
    https://www.cisa.gov/news-events/alerts/2023/11/26/cisa-and-uk-ncsc-unveil-joint-guidelines-secure-ai-system-development

     Scattered Spider Blog-
    https://www.reliaquest.com/blog/scattered-spider-attack-analysis-account-compromise/

    44 min
  • Weekly: ALPHV SEC Complaint, Scattered Spider Case Study, Sandworm Attacks

    In this episode of ShadowTalk, host Ivan, along with Brandon and Colin discuss the latest news in cyber security and threat research. Topics this week include:

    • AlphaV filing a complaint with the SEC
    • ReliaQuest case study on the Scattered Spider attack
    • Sandworm hacker group conducts "largest ever" attack on Danish infrastructure

    Resources:

    • https://www.reliaquest.com/blog/scattered-spider-attack-analysis-account-compromise/
    33 min
  • Weekly: CitrixBleed, Taking a Proactive Approach to IR, BiBi wiper targets Israeli Organizations

    In this episode of ShadowTalk, host Chris, along with Kim, discuss the latest news in cyber security and threat research. Topics this week include:

    • CitrixBleed vulnerability mass targeted by threat actors
    • Taking the burden from incidents responders by taking proactive steps
    • Hacktivists targeting Israeli organizations with "BiBi" data wiping malware


    Resources:

    https://www.reliaquest.com/blog/citrix-bleed-vulnerability-background-and-recommendations/

    30 min
  • Weekly: Apache ActiveMQ and Atlassian Confluence, SEC files charges, QR code phishing

    In this episode of ShadowTalk, host Ivan Righi, along with ReliaQuest's CISO Rick Holland and Detection Researcher Marken Teder, discuss the latest news in cyber security and threat research. Topics this week include:

    • Apache ActiveMQ vulnerability (CVE-2023-46604) exploited by ransomware gangs
    • Discussion over charges filed by the US SEC against SolarWinds
    • Active exploitation of a Critical Atlassian Confluence flaw (CVE-2023-22518)
    • An overview of QR code phishing threats

    Resources:

    • https://event.on24.com/wcc/r/4387339/A63BC17298406ECD68AABFFEF416702B?partnerref=organic
    36 min
  • Weekly: SolarWinds SEC Charges, Vulnerabilities Roundup, AI Executive Order

    In this episode of ShadowTalk, host Kim, along with Caroline and Corey, discuss the latest news in cyber security and threat research. Topics this week include:

    • The charges filed by the US SEC against SolarWinds
    • A sneak-peak of the findings from our Vulnerabilities Roundup blog
    • An overview of some vulnerabilities impacting users right now
    • The Executive Order issued by the Biden administration on artificial intelligence.


    34 min
  • Weekly: Q3 Ransomware Report, ServiceNow Vulnerability, Okta Incident

    In this episode of ShadowTalk, Host Chris Morgan is joined by one of ReliaQuest's CISO's Rick Holland, Threat Hunter Brian Kelly and Threat Intelligence Analyst Ivan Righi to discuss the latest news in cyber security and threat research. Topics this week include:

    • The findings of ReliaQuest's Quarterly Ransomware Report recapping Q3 2023 activity.
    •  ServiceNow vulnerability and what it means for you
    • The latest on a security incident pertaining to authentication provider, Okta.

    Resources:

    • https://www.reliaquest.com/blog/ransomware-trends-q3-2023/



    36 min

About ShadowTalk: Powered by ReliaQuest

From the publisher's feed

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical…

More shows like ShadowTalk: Powered by ReliaQuest

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,644 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Click Here by Recorded Future News

Click Here

418 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics by SPYSCAPE

True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics

1,943 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Cyber Hack by BBC World Service

Cyber Hack

1,594 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

46 Listeners

The Economics Show by Financial Times

The Economics Show

139 Listeners